Ireland's data protection commission fines TikTok 345 million euros over child privacy violations
Guardii Analysis
Ireland's Data Protection Commission announced on 27 September 2024 a fine of 345 million euros against TikTok for violations of the EU General Data Protection Regulation related to the processing of children's personal data, including making accounts of users aged 13 to 17 public by default and failing to provide transparent information to child users and their parents. The decision follows a two-year investigation and represents one of the largest GDPR penalties to date, reflecting the regulator's view that TikTok did not adequately safeguard minors' privacy during the period under review.
Privacy-by-default settings reduce data exposure but do not address in-conversation harms that unfold in direct messages irrespective of account visibility. Technology that identifies grooming, sextortion and coercion as the exchange develops—Guardii's operational model across TikTok, Instagram, Snapchat, Discord and Roblox—protects the child at the point of contact, detecting escalation and targeting patterns in real time and surfacing the threat to a parent or safeguarding professional before the interaction reaches crisis. Where regulatory enforcement corrects platform design retrospectively, real-time pattern recognition built into messaging infrastructure operates continuously, addressing the conduct that privacy settings alone cannot prevent and ensuring that a child in danger is visible to those in a position to act.
